WSO2 APIKeys API

The APIKeys API from WSO2 — 16 operation(s) for apikeys.

Operations 16

GET /api-keys Get all API Keys #
POST /api-keys/revoke Revoke an API Key #
POST /apis/{apiId}/api-keys/generate Generate API Key #
POST /apis/{apiId}/api-keys/regenerate Regenerate API Key #
GET /apis/{apiId}/api-keys Get API Key(s) of a Given API #
POST /apis/{apiId}/api-keys/revoke Revoke API Key #
POST /apis/{apiId}/api-keys/associate Create an association for the API Key #
POST /apis/{apiId}/api-keys/dissociate Remove an Association for the API Key #
POST /applications/{applicationId}/api-keys/{keyType}/generate Generate API Key #
POST /applications/{applicationId}/api-keys/{keyType}/regenerate Regenerate API Key #
GET /applications/{applicationId}/api-keys/{keyType} Get API Key(s) of a Given Type #
POST /applications/{applicationId}/api-keys/{keyType}/revoke Revoke API Key #
GET /applications/{applicationId}/api-keys/{keyType}/subscriptions Get Subscribed APIs with API Key(s) of a Given Type #
POST /applications/{applicationId}/api-keys/{keyType}/associate Associate an API Key to the Application #
POST /applications/{applicationId}/api-keys/{keyType}/dissociate Remove the association of the API Key to the Application #
GET /applications/{applicationId}/api-keys/{keyType}/associations Get API Key associations of a Given Type #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/wso2-apikeys-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

wso2-apikeys-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: WSO2 API Manager - Admin Advanced Policy (Collection) Advanced Policy (Collection) API Keys API
  description: "This document specifies a **RESTful API** for WSO2 **API Manager** - **Admin Portal**.\nPlease see [full OpenAPI Specification](https://raw.githubusercontent.com/wso2/carbon-apimgt/master/components/apimgt/org.wso2.carbon.apimgt.rest.api.admin.v1/src/main/resources/admin-api.yaml) of the API which is written using [OAS 3.0](http://swagger.io/) specification.\n\n# Authentication\nThe Admin REST API is protected using OAuth2 and access control is achieved through scopes. Before you start invoking\nthe the API you need to obtain an access token with the required scopes. This guide will walk you through the steps\nthat you will need to follow to obtain an access token.\nFirst you need to obtain the consumer key/secret key pair by calling the dynamic client registration (DCR) endpoint. You can add your preferred grant types\nin the payload. A sample payload is shown below.\n```\n  {\n  \"callbackUrl\":\"www.example.com\",\n  \"clientName\":\"rest_api_admin\",\n  \"owner\":\"admin\",\n  \"grantType\":\"client_credentials password refresh_token\",\n  \"saasApp\":true\n  }\n```\nCreate a file (payload.json) with the above sample payload, and use the cURL shown bellow to invoke the DCR endpoint. Authorization header of this should contain the\nbase64 encoded admin username and password.\n**Format of the request**\n```\n  curl -X POST -H \"Authorization: Basic Base64(admin_username:admin_password)\" -H \"Content-Type: application/json\"\n  \\ -d @payload.json https://<host>:<servlet_port>/client-registration/v0.17/register\n```\n**Sample request**\n```\n  curl -X POST -H \"Authorization: Basic YWRtaW46YWRtaW4=\" -H \"Content-Type: application/json\"\n  \\ -d @payload.json https://localhost:9443/client-registration/v0.17/register\n```\nFollowing is a sample response after invoking the above curl.\n```\n{\n\"clientId\": \"fOCi4vNJ59PpHucC2CAYfYuADdMa\",\n\"clientName\": \"rest_api_admin\",\n\"callBackURL\": \"www.example.com\",\n\"clientSecret\": \"a4FwHlq0iCIKVs2MPIIDnepZnYMa\",\n\"isSaasApplication\": true,\n\"appOwner\": \"admin\",\n\"jsonString\": \"{\\\"grant_types\\\":\\\"client_credentials password refresh_token\\\",\\\"redirect_uris\\\":\\\"www.example.com\\\",\\\"client_name\\\":\\\"rest_api_admin\\\"}\",\n\"jsonAppAttribute\": \"{}\",\n\"tokenType\": null\n}\n```\nNote that in a distributed deployment or IS as KM separated environment to invoke RESTful APIs (product APIs), users must generate tokens through API-M Control Plane's token endpoint.\nThe tokens generated using third party key managers, are to manage end-user authentication when accessing APIs.\n\nNext you must use the above client id and secret to obtain the access token.\nWe will be using the password grant type for this, you can use any grant type you desire.\nYou also need to add the proper **scope** when getting the access token. All possible scopes for Admin REST API can be viewed in **OAuth2 Security** section\nof this document and scope for each resource is given in **authorizations** section of resource documentation.\nFollowing is the format of the request if you are using the password grant type.\n```\ncurl -k -d \"grant_type=password&username=<admin_username>&password=<admin_passowrd>&scope=<scopes seperated by space>\"\n\\ -H \"Authorization: Basic base64(cliet_id:client_secret)\"\n\\ https://<host>:<server_port>/oauth2/token\n```\n**Sample request**\n```\ncurl https://localhost:9443/oauth2/token -k \\\n-H \"Authorization: Basic Zk9DaTR2Tko1OVBwSHVjQzJDQVlmWXVBRGRNYTphNEZ3SGxxMGlDSUtWczJNUElJRG5lcFpuWU1h\" \\\n-d \"grant_type=password&username=admin&password=admin&scope=apim:admin apim:tier_view\"\n```\nShown below is a sample response to the above request.\n```\n{\n\"access_token\": \"e79bda48-3406-3178-acce-f6e4dbdcbb12\",\n\"refresh_token\": \"a757795d-e69f-38b8-bd85-9aded677a97c\",\n\"scope\": \"apim:admin apim:tier_view\",\n\"token_type\": \"Bearer\",\n\"expires_in\": 3600\n}\n```\nNow you have a valid access token, which you can use to invoke an API.\nNavigate through the API descriptions to find the required API, obtain an access token as described above and invoke the API with the authentication header.\nIf you use a different authentication mechanism, this process may change.\n\n# Try out in Postman\nIf you want to try-out the embedded postman collection with \"Run in Postman\" option, please follow the guidelines listed below.\n* All of the OAuth2 secured endpoints have been configured with an Authorization Bearer header with a parameterized access token. Before invoking any REST API resource make sure you run the `Register DCR Application` and `Generate Access Token` requests to fetch an access token with all required scopes.\n* Make sure you have an API Manager instance up and running.\n* Update the `basepath` parameter to match the hostname and port of the APIM instance.\n\n[![Run in Postman](https://run.pstmn.io/button.svg)](https://app.getpostman.com/run-collection/32294946-71bea2bc-f808-4208-a4f6-861ede6f0434)\n"
  contact:
    name: WSO2
    url: https://wso2.com/api-manager/
    email: architecture@wso2.com
  license:
    name: Apache 2.0
    url: http://www.apache.org/licenses/LICENSE-2.0.html
  version: v4
servers:
- url: https://apis.wso2.com/api/am/admin/v4
tags:
- name: APIKeys
paths:
  /api-keys:
    get:
      tags:
      - APIKeys
      summary: Get all API Keys
      description: 'Retrieve all API Keys.

        '
      operationId: getAllAPIKeys
      responses:
        200:
          description: 'OK.

            API keys returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:admin
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://127.0.0.1:9443/api/am/admin/v4/api-keys"'
  /api-keys/revoke:
    post:
      tags:
      - APIKeys
      summary: Revoke an API Key
      description: 'Revoke an API Key for the API

        '
      operationId: revokeAPIKeyFromAdmin
      requestBody:
        description: 'API key revoke object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyRevokeRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key revoked successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:admin
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://127.0.0.1:9443/api/am/admin/v4/api-keys/ght65523-7650-4255-84fa-6cb171c1f779/d7cf8523-9180-4255-84fa-6cb171c1f779/PRODUCTION/revoke"'
  /apis/{apiId}/api-keys/generate:
    post:
      tags:
      - APIKeys
      summary: Generate API Key
      description: 'Generate a self contained API Key for the API

        '
      operationId: generateApiBoundApiKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key generation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIAPIKeyGenerateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key generated.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/generate"'
  /apis/{apiId}/api-keys/regenerate:
    post:
      tags:
      - APIKeys
      summary: Regenerate API Key
      description: 'Regenerate a self contained API Key for the API specified by the key UUID

        '
      operationId: regenerateAPIBoundAPIKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key renewal request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyRenewRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key regenerated successfully.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/regenerate"'
  /apis/{apiId}/api-keys:
    get:
      tags:
      - APIKeys
      summary: Get API Key(s) of a Given API
      description: 'Retrieve self contained API Key(s) for the API.

        '
      operationId: getAPIBoundAPIKeys
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-None-Match'
      responses:
        200:
          description: 'OK.

            API key(s) of a given API are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIAPIKeyList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys"'
  /apis/{apiId}/api-keys/revoke:
    post:
      tags:
      - APIKeys
      summary: Revoke API Key
      description: 'Revoke a self contained API Key for the API specified by the key UUID

        '
      operationId: revokeAPIBoundAPIKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key revocation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIAPIKeyRevokeRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key revoked successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/revoke"'
  /apis/{apiId}/api-keys/associate:
    post:
      tags:
      - APIKeys
      summary: Create an association for the API Key
      description: 'Create an association for a self contained API Key for the API

        '
      operationId: associateAPIKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key association request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIAPIKeyAssociateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key associated successfully.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyAssociation'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/associate"'
  /apis/{apiId}/api-keys/dissociate:
    post:
      tags:
      - APIKeys
      summary: Remove an Association for the API Key
      description: 'Remove an association a self contained API Key for the API specified by the key UUID

        '
      operationId: dissociateAPIKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key dissociation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyDissociateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Removed association for the Api key successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/dissociate"'
  /applications/{applicationId}/api-keys/{keyType}/generate:
    post:
      tags:
      - APIKeys
      summary: Generate API Key
      description: 'Generate a self contained API Key for the application

        '
      operationId: applicationsApplicationIdApiKeysKeyTypeGeneratePost
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key generation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyGenerateRequest'
        required: false
      responses:
        200:
          description: 'OK.

            Api key generated.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/generate"'
  /applications/{applicationId}/api-keys/{keyType}/regenerate:
    post:
      tags:
      - APIKeys
      summary: Regenerate API Key
      description: 'Regenerate a self contained API Key for the application specified by the key UUID

        '
      operationId: regenerateAppBoundAPIKey
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key renewal request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyRenewRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key regenerated successfully.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/regenerate"'
  /applications/{applicationId}/api-keys/{keyType}:
    get:
      tags:
      - APIKeys
      summary: Get API Key(s) of a Given Type
      description: 'Retrieve self contained API Key(s) for the application specifying the key type in the URI.

        '
      operationId: getAppBoundAPIKeys
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-None-Match'
      responses:
        200:
          description: 'OK.

            API key(s) of given type are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyList_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION"'
  /applications/{applicationId}/api-keys/{keyType}/revoke:
    post:
      tags:
      - APIKeys
      summary: Revoke API Key
      description: 'Revoke a self contained API Key for the application

        '
      operationId: applicationsApplicationIdApiKeysKeyTypeRevokePost
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key revoke request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyRevokeRequest_2'
        required: true
      responses:
        200:
          description: 'OK.

            Api key revoked successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/revoke"'
  /applications/{applicationId}/api-keys/{keyType}/subscriptions:
    get:
      tags:
      - APIKeys
      summary: Get Subscribed APIs with API Key(s) of a Given Type
      description: 'Retrieve subscribed APIs with non-associated API Key(s) for the application specifying the key type in the URI.

        '
      operationId: getSubscribedAPIsWithAPIKeys
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-None-Match'
      responses:
        200:
          description: 'OK.

            Subscribed APIs along with the non-associated API key(s) of given type are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SubscribedAPIWithApiKeyList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/subscriptions"'
  /applications/{applicationId}/api-keys/{keyType}/associate:
    post:
      tags:
      - APIKeys
      summary: Associate an API Key to the Application
      description: 'Create an association to a self contained API Key for the application

        '
      operationId: associateAPIKeyToApp
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key association request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AppAPIKeyAssociateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key associated successfully.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyAssociation'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/associate"'
  /applications/{applicationId}/api-keys/{keyType}/dissociate:
    post:
      tags:
      - APIKeys
      summary: Remove the association of the API Key to the Application
      description: 'Remove the association to a self contained API Key for the application

        '
      operationId: dissociateAPIKeyFromApp
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key dissociation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyDissociateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Removed association for the API key successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/dissociate"'
  /applications/{applicationId}/api-keys/{keyType}/associations:
    get:
      tags:
      - APIKeys
      summary: Get API Key associations of a Given Type
      description: 'Retrieve API key associations for the application specifying the key type in the URI.

        '
      operationId: getAPIKeyAssociationsForApp
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-None-Match'
      responses:
        200:
          description: 'OK.

            API key associations of given type are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyAssociationList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/associations"'
components:
  schemas:
    APIAPIKeyList:
      title: API Keys List
      type: object
      properties:
        count:
          type: integer
          description: 'Number of API keys returned.

            '
          example: 1
        list:
          type: array
          items:
            $ref: '#/components/schemas/APIAPIKeyInfo'
    APIKeyRenewRequest:
      title: API Key renewal request object
      type: object
      required:
      - keyUUID
      properties:
        keyUUID:
          type: string
          description: The UUID of the API key
    APIKeyRevokeRequest_2:
      title: API Key revoke request object
      type: object
      oneOf:
      - required:
        - apikey
      - required:
        - keyUUID
      properties:
        apikey:
          type: string
          description: API Key to revoke
          example: eyJoZWxsbyI6IndvcmxkIn0=.eyJ3c28yIjoiYXBpbSJ9.eyJ3c28yIjoic2lnbmF0dXJlIn0=
        keyUUID:
          type: string
          description: The UUID of the API key
    APIKeyList_2:
      title: API Keys List
      type: object
      properties:
        count:
          type: integer
          description: 'Number of API keys returned.

            '
          example: 1
        list:
          type: array
          items:
            $ref: '#/components/schemas/APIKeyInfo'
    APIKeyDissociateRequest:
      title: API Key dissociation request object
      type: object
      required:
      - keyUUID
      properties:
        keyUUID:
          type: string
          description: The UUID of the API key
    APIAPIKeyRevokeRequest:
      title: API Key revoke request object
      type: object
      required:
      - keyUUID
      properties:
        keyUUID:
          type: string
          description: The UUID of the API key
    AppAPIKeyAssociateRequest:
      title: API Key association request object
      type: object
      required:
      - keyUUID
      - apiUUID
      properties:
        apiUUID:
          type: string
          description: The unique identifier of the API.
          example: 2962f3bb-8330-438e-baee-0ee1d6434ba4
        keyUUID:
          type: string
          description: The UUID of the API key
    Error:
      title: Error object returned with 4XX HTTP status
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: integer
          description: Error code
          format: int64
        message:
          type: string
          description: Error message.
        description:
          type: string
          description: 'A detail description about the error message.

            '
        moreInfo:
          type: string
          description: 'Preferably an url with more details about the error.

            '
        error:
          type: array
          description: 'If there are more than one error list them out.

            For example, list out validation errors by each field.

            '
          items:
            $ref: '#/components/schemas/ErrorListItem'
    SubscribedAPIWithApiKeyList:
      title: Subscribed APIs with non-associated API keys
      type: object
      properties:
        count:
          type: integer
          description: 'Number of subscribed APIs with API keys returned.

            '
          example: 1
        list:
          type: array
          items:
            $ref: '#/components/schemas/APIWithKeyInfo'
    APIKeyAssociation:
      title: API Key association
      type: object
      properties:
        keyName:
          type: string
          description: API Key name
          example: Test_Key
        apiName:
          type: string
          description: API name
          example: NotificationAPI
        applicationName:
          type: string
          description: Application name
          example: DefaultApplication
    APIWithKeyInfo:
      title: API with API Key
      type: object
      properties:
        keyName:
          type: string
          description: API Key name
          example: Test_Key
        keyUUID:
          type: string
          description: The UUID of the API key
        apiName:
          type: string
          description: API name
          example: NotificationAPI
        apiUUID:
          type: string
          description: The UUID of the associated API
    ErrorListItem:
      title: Description of individual errors that may have occurred during a request.
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: Error code
        message:
          type: string
          description: 'Description about individual errors occurred

            '
    APIKey:
      title: API Key details to invoke APIs
      type: object
      properties:
        keyUUID:
          type: string
          description: The UUID of the API key
        keyName:
          type: string
          description: API Key name
          example: Test_Key
        apiName:
          type: string
          description: API Name
          example: NotificationsAPI
        applicationName:
          type: string
          description: Application Name
          example: DefaultApplication
        keyType:
          typ

# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/wso2/refs/heads/main/openapi/wso2-apikeys-api-openapi.yml